Privacy Policy

Last updated: 13 July 2026

Omiai is a dating app. To help you meet someone, we have to process your personal data — and you have every right to know exactly what we collect, why, and who we share it with. This document explains that in plain language. There is no fine print here: if anything is unclear, write to us.

1. Who controls your data

The controller of your personal data is Recruit Europe Sp. z o.o., with its registered office in Wrocław, Poland (ul. Legnicka 17 lok. 76, 53-671 Wrocław), entered in the register of entrepreneurs under KRS no. 0000429981, VAT no. (NIP) 8971784362, REGON 021952135 — the operator of the Omiai app (“we”, “us”).

  • For anything related to your personal data and privacy, write to: kontakt@omiai.eu.
  • You can also use the tools inside the app: Profile → Information → Data privacy.

2. What data we collect

We collect three kinds of data: what you give us, what is generated as you use the app, and what we receive from third parties.

2.1. Data you give us

  • Account data: your email address and password (stored only as a hash — we never see your password) and, if you enable two-factor authentication, the data needed to support it.
  • Profile data: nickname, date of birth, gender, the gender of people you want to meet, your “about me” text, interests, location (city/region) and any other fields you choose to fill in.
  • Photos: your profile picture and gallery photos, together with the file metadata.
  • Content you create: chat messages, likes, super likes, reports and blocks of other users.
  • Correspondence with us: support requests, abuse reports and requests concerning your rights.

2.2. Special categories of data (sensitive data)

By creating a profile and stating the gender of people you want to meet, you may reveal information about your sexual orientation. This is a special category of data under Article 9 GDPR. We process it solely on the basis of your explicit consent (Article 9(2)(a) GDPR), given by knowingly providing this information in your profile, and only to show you relevant suggestions. You can change or delete it at any time in your profile settings. We do not ask for data about your health, political opinions, religion or trade union membership — please do not put such data in your profile text or photos.

2.3. Data collected automatically

  • Technical data: IP address, device type and model, operating system, app version, device identifiers, language settings.
  • Usage data: when and how long you use the app, which profiles you view, which features you use, which screens you open.
  • Location: an approximate location derived from your IP address and — if you grant permission in your operating system — a more precise device location, used to find people within the radius you choose. You can withdraw this permission in your phone settings at any time.
  • Security data: information about logins, failed login attempts and behaviour indicating spam, fraud or breach of our terms.
  • Cookies and similar technologies — see section 4.

2.4. Data from third parties

  • Google sign-in: if you sign in with Google, we receive your email address and basic profile data to the extent you consent to.
  • Payment providers: information about the status of your payments and subscription. We never receive or store full payment card numbers.
  • Other users: reports and information they provide about you (for example, a report of a breach of our terms).

3. Why we process your data and on what legal basis

We do not process data “just in case”. Every purpose has a defined legal basis under Article 6 (and, for sensitive data, Article 9) GDPR.

  • Running your account and providing the service — showing profiles, matches, chat, in-app notifications. Basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Suggesting matches and searching within a radius — based on your preferences and location. Basis: performance of a contract, and for sensitive data and precise location — your consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR).
  • Handling payments and Premium subscriptions, including settlement and accounting duties. Basis: performance of a contract and a legal obligation (Art. 6(1)(b) and (c) GDPR).
  • Safety, moderation and abuse prevention — detecting spam, fake accounts and fraud, handling reports, enforcing our terms. Basis: our legitimate interest in protecting our users and the service (Art. 6(1)(f) GDPR).
  • Push and email notifications about matches, messages and account activity. Basis: performance of a contract; push notifications are only sent after you grant permission in your operating system.
  • Our own marketing and information about promotions — only if you consent. Basis: consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
  • Analytics and product development — understanding which features work and fixing bugs. Cookie-based analytics only runs after you consent in the cookie banner.
  • Establishing, exercising and defending legal claims and meeting our statutory duties (including under the Digital Services Act). Basis: legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR).

4. Cookies and similar technologies

On omiai.eu we use cookies and browser local storage. Necessary cookies (keeping you signed in, security, remembering your banner choice) are always active — the site does not work without them. Analytics and marketing cookies are only set after you consent.

  • You can change your choice at any time via “Manage cookies” in the site footer.
  • The mobile app does not use cookies; the equivalent functions rely on device storage and system identifiers.

5. Who we share your data with

We do not sell your data. We share it only as far as necessary to run the service, with carefully chosen providers who act on our instructions under data processing agreements.

  • Other users: your profile (nickname, age, photos, description, approximate location) is visible to other Omiai users according to your privacy settings. Messages are seen by the person you send them to. Remember that anything you put in your profile or in a chat can be saved or passed on by others — only publish what you are happy to show.
  • Supabase (database, authentication, photo storage, realtime messaging) — the core infrastructure where app data is stored.
  • Payment providers — Stripe and, in the mobile apps, the Apple App Store and Google Play — handling Premium purchases.
  • Notification providers — Firebase Cloud Messaging (Android), Apple Push Notification service (iOS) and our transactional email provider (system emails).
  • Google — Google sign-in and location suggestions (city/region) when you complete your profile.
  • Providers supporting our analytics and infrastructure, strictly within the scope you consented to or which is necessary to run the service.
  • Public authorities — where we are legally obliged to, for example at the request of a court, prosecutor or the police, and where necessary to prevent an imminent threat to life or health.

6. Transfers outside the European Economic Area

Some of our providers (including push notification and Google services) are based outside the EEA. In those cases we transfer data only on the basis of the mechanisms set out in Chapter V GDPR — an adequacy decision of the European Commission or standard contractual clauses, supplemented by additional technical safeguards (including encryption). We will provide a copy of the safeguards used on request.

7. How long we keep your data

  • Account and profile data — for as long as you have an account.
  • Once you request deletion, your profile immediately stops being visible to other users and your account is marked for deletion. For 30 days you can change your mind and restore it.
  • After 30 days we permanently delete your profile, photos, messages, likes and matches. The details are described on our “Account and data deletion” page.
  • Billing data and accounting documents are kept for the period required by tax law (as a rule, 5 years from the end of the year in which the tax payment deadline fell).
  • Data needed to demonstrate our compliance, defend against claims and prevent users removed for serious violations (such as harassment or fraud) from simply signing up again is kept, in a limited scope, for the applicable limitation period.

8. Your rights

In relation to the processing of your data, you have the following rights:

  • The right of access to your data and to obtain a copy of it (Art. 15 GDPR).
  • The right to rectify inaccurate data and complete incomplete data (Art. 16 GDPR).
  • The right to erasure — the “right to be forgotten” (Art. 17 GDPR).
  • The right to restrict processing (Art. 18 GDPR).
  • The right to data portability — to receive your data in a structured, commonly used format (Art. 20 GDPR).
  • The right to object to processing based on our legitimate interest (Art. 21 GDPR).
  • The right to withdraw consent at any time — without affecting the lawfulness of processing carried out before the withdrawal.
  • The right to lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warsaw) if you believe we process your data unlawfully.

You can exercise most of these rights yourself in the app: Profile → Information → Data privacy (download a copy of your data, delete your account) and in your profile settings. You can also write to kontakt@omiai.eu — we reply within one month at the latest.

9. Matching and automated decisions

The order of the profiles we show you is determined by an algorithm that takes into account your preferences, distance, activity in the app and mutual interest, among other things. We do not make decisions producing legal effects concerning you based solely on automated processing. Automated systems help us detect spam and abuse, but a decision to permanently block an account is reviewed by a human, and you can appeal against a block by writing to kontakt@omiai.eu.

10. Security

We apply technical and organisational measures appropriate to the risk: encrypted connections (TLS), encryption at rest, row-level access control in the database (RLS), password storage as hashes only, and optional two-factor authentication (TOTP), which we strongly encourage you to enable. No method of transmission or storage is 100% secure, however — if you suspect someone has accessed your account, change your password immediately and contact us.

11. Children

Omiai is for adults only. We do not create accounts for people under 18 and we do not knowingly collect their data. If we learn that an account belongs to a minor, we will delete it along with its data. If you suspect a child is using Omiai, write to kontakt@omiai.eu.

12. Changes to this policy

We may update this policy — for example when we add a new feature or change a provider. We will inform you of any material change in the app or by email before it takes effect. The date of the last update is shown at the top of this page.

13. Contact

Have a question about your data, or want to exercise any of the rights described above? Write to kontakt@omiai.eu or by post: Recruit Europe Sp. z o.o., ul. Legnicka 17 lok. 76, 53-671 Wrocław, Poland.